Fraud and AML Software Selling to Tier-1 and Tier-2 Banks — 60-Min Training
PULSEKNOWLEDGE LIBRARYQuality
Certified

Fraud and AML software sales to Tier-1 and Tier-2 banks are won by choosing deliberately between a fraud-first wedge and a compliance-first wedge, then proving false-positive economics on the bank's own sanitized data. This 60-minute training teaches sellers to mobilize the Chief Risk Officer and Chief Compliance Officer together, and to time displacement against the incumbent's renewal.
Two wedges into the same bank: fraud-first versus compliance-first
Every enterprise deal in this category starts with a choice most sellers make by accident: which door you walk through. The fraud-first wedge leads with real-time transaction scoring, card-not-present detection, account-takeover prevention, and fraud dollars blocked. Its economic buyer is the Chief Risk Officer, and its proof is a loss-avoidance number the bank can tie to its own chargeback and write-off ledger. The compliance-first wedge leads with sanctions screening, transaction monitoring, alert triage, and Suspicious Activity Report production. Its economic buyer is the Chief Compliance Officer, and its proof is regulator-defensibility — model documentation, audit trail completeness, and the ability to explain why an alert fired eighteen months after the fact.
These are not two ways to describe the same sale. They have different budget lines, different urgency clocks, and different failure modes. Fraud budgets move on quarterly loss data and tend to be discretionary; if losses spike, money appears fast. Compliance budgets move on examination findings and consent orders; they are slower to release but far harder to cut once committed, because the bank cannot un-promise a regulator that it will remediate. A seller who leads compliance-first at a bank with no recent examination pressure will find a polite, endless evaluation. A seller who leads fraud-first at a bank operating under a remediation commitment will be told, accurately, that this quarter's engineering capacity belongs to the regulator.
The training's core teaching point is that you must pick one wedge as the primary and treat the other as the mandatory second signature. In practice, the fraud-first wedge closes faster but lands smaller and is more replaceable at renewal, because fraud performance is measurable and therefore comparable — the next vendor can benchmark against you the same way you benchmarked against the incumbent. The compliance-first wedge takes longer to close, but once a bank's transaction-monitoring rules, tuning documentation, and SAR workflow live in your platform, switching costs are severe, because migrating means re-documenting the whole model inventory for the examiner. Sellers optimizing for this year's quota tend toward fraud-first. Sellers optimizing for net revenue retention should be pushed toward compliance-first or, better, a fraud-first land with a contractually scoped compliance expansion.

There is a third path worth naming so the room can reject it explicitly: the platform-first pitch, where the seller opens with "we do fraud and AML and KYC and sanctions on one data layer." It sounds efficient and it fails reliably, because it asks two executives with separate budgets to co-sponsor an abstraction before either has felt a specific problem solved. Platform consolidation is a renewal-and-expansion story, not a land story. Sell the wedge, earn the platform.
Tier-1 versus Tier-2: the same product, two different sales motions
The second comparison the room must internalize is buyer size. Tier-1 institutions — the largest national and global banks — have internal financial-crime engineering teams, in-house model risk management functions, and a build-versus-buy reflex. Your competitor at a Tier-1 is frequently not another vendor but the bank's own platform team, which has already built a rules engine and a case manager and considers your product a feature. Tier-2 institutions — large regionals, mid-size nationals, and sizable credit unions — usually cannot staff a model risk validation team deep enough to defend a homegrown machine-learning model to an examiner, which makes vendor documentation a genuine asset rather than a redundancy.

That difference reshapes discovery. At a Tier-1, your qualifying question is not "do you have a problem" but "which part of your stack are you willing to not own?" The winnable scope is usually a specific, hard, unglamorous layer: entity resolution across siloed systems, real-time scoring at a latency the internal batch system cannot hit, or sanctions screening against a list-update cadence the internal team is tired of maintaining. At a Tier-2, the winnable scope is broader and the conversation is closer to a classic platform replacement, because the bank is genuinely trying to reduce the number of vendors and internal systems its small compliance team must operate.
Procurement differs just as sharply. Tier-1 banks run third-party risk management processes that will consume months on their own: security questionnaires, penetration test evidence, business continuity documentation, model risk validation packages, on-site or virtual vendor assessments, and sometimes a regulator notification requirement for critical service providers. Tier-2 banks run a lighter version of the same, but with fewer people to run it, which paradoxically can be slower in wall-clock time because the one person who owns vendor risk also owns four other things.
The practical coaching move is to make every AE state, out loud, which motion they are running on each named account. If it is Tier-1, the mutual action plan must include third-party risk milestones as first-class line items with named owners, because those milestones — not the technical evaluation — are what actually determine the close date. If it is Tier-2, the plan must include an explicit internal-champion capacity check: does the person championing this have the hours to run an evaluation on top of their day job, and if not, what does your team do to carry the load?

How to decide which wedge and which motion to run
Give the room a decision procedure rather than a philosophy. The inputs are all discoverable in the first two conversations, and each one has a clean bias attached to it.
Start with regulatory posture. Ask directly whether the institution is operating under any published enforcement action, consent order, or matter requiring attention, and when the last examination closed. Public enforcement actions from the OCC, the Federal Reserve, and the FDIC are published, so this is verifiable before the call — a seller who walks in without having checked has skipped free intelligence. If there is active remediation, the compliance-first wedge is the only wedge, and the buying committee's center of gravity sits with the Chief Compliance Officer and the bank's remediation program office.
Next, check loss trajectory. Ask for fraud loss as a trend, not a total: is it up or down over the last four quarters, and which channel is driving the change? A visible upward trend in a specific channel is the single most reliable fraud-first trigger, because it creates a named owner with a named number who is already being asked about it in board materials.

Third, check alert volume against analyst headcount. The ratio of monthly alerts to full-time triage analysts tells you whether the pain is operational. A team drowning in alerts will engage on false-positive reduction immediately, and that conversation belongs to whichever executive owns the triage team — which varies by bank and is worth asking rather than assuming.
Fourth, check the incumbent's contract clock. If renewal is inside nine months, run a displacement motion with a compressed proof plan. If it is beyond eighteen months, run a coexistence land on a channel or product the incumbent does not cover, and build production evidence you can point to when the renewal finally arrives.
Run the decision tree live in the session against two real accounts from the room's pipeline. The failure you are hunting for is the account that reaches the "no compelling event" node and is nonetheless sitting in the current-quarter forecast. That is the highest-value five minutes of the hour.

The numbers each wedge has to survive
Sellers lose credibility in this category by quoting industry statistics instead of the customer's own operating numbers. The discipline to teach is that every claim you make should be constructed from figures the bank gave you. That means discovery has to collect a specific numeric set, and the room should practice asking for each one in plain language.
For the fraud-first wedge, collect: gross fraud losses by channel for the trailing four quarters; the split between losses absorbed by the bank and losses passed to the network or customer; decline rate and estimated false-decline cost, since over-blocking legitimate transactions is a revenue problem the CRO usually owns quietly; the current detection latency in milliseconds for real-time authorization decisions and the hard latency ceiling the payment flow allows; and the manual review queue volume with its per-case handling time. False declines matter disproportionately in the pitch because they connect a risk conversation to a revenue conversation, and revenue conversations get funded faster.

For the compliance-first wedge, collect: monthly alert volume by scenario; the proportion of alerts closed at first-level review without escalation, which is the practical definition of the false-positive burden; the number of full-time analysts and contractors in triage and their loaded cost; the number of SARs filed annually and the average analyst hours per filing; sanctions screening hit rates and the time to clear a hit; and the age of the last model tuning exercise with its documentation status. Do not quote an industry false-positive benchmark in the room or on the call — the number varies enormously by institution and scenario, and a sophisticated compliance officer will spend the next ten minutes correcting you instead of listening to you.
Build the business case arithmetic from those figures in front of the customer. If the bank runs a triage team of a known size at a known loaded cost, and you can support a modeled reduction in first-level alert volume, the annual capacity saving is a multiplication the customer performs with you rather than a claim you assert. Always express the outcome as capacity redeployed rather than headcount eliminated, because compliance leaders rarely get to cut staff under examination scrutiny — but they will happily move analysts from clearing noise to investigating real cases, and that framing survives the CCO's internal retelling.
On pricing, teach the room the structural comparison rather than a price list. Fraud detection tends to price on transaction or decision volume, which aligns cost to the bank's growth and is easy for finance to model but exposes the bank to cost spikes in high-volume periods. AML transaction monitoring tends to price on some combination of monitored accounts, entities, or platform tiers, which is more predictable but harder to compare across vendors. Per-seat pricing appears mostly in case management and investigator tooling and is the weakest structure to defend at renewal, because seat counts are the first thing a cost-cutting exercise attacks. When the customer asks for a discount, tie every increment to term length and to a named commitment — reference logo rights, a case study, an executive reference call, a phased expansion into a second product line — so the concession buys something durable rather than simply lowering the baseline the next negotiation starts from.

The trade-off to state honestly in the room: transaction-based pricing wins more deals and produces more volatile revenue; committed-tier pricing produces cleaner forecasts and loses some price-sensitive Tier-2 deals to competitors willing to meter. Neither is wrong. What is wrong is a seller who has never articulated which one they are proposing and why.
Sequencing the deal from first call to signed order form
The last block of the hour is mechanical, and it should be. Give the room a sequence with named artifacts, because artifacts are what survive rep turnover and manager inspection.
The first meeting is a two-executive discovery or it is a rescheduled meeting. This is the single rule with the most leverage in the entire motion. A discovery with the Chief Risk Officer alone produces a fraud business case that the Chief Compliance Officer will later reopen from scratch; a discovery with the compliance side alone produces a control narrative that the risk side will judge as an unfunded cost. Getting both in one room takes two extra weeks of scheduling and saves two months of sequential re-selling. Teach the room to trade for it explicitly: offer a shorter meeting, offer to come on site, offer to prepare a written pre-read so the executives arrive informed.

The pre-read is the second artifact. One page, sent seventy-two hours ahead: what you understand about the institution from public sources, the three questions you want to answer, and what the customer will get from the hour. It converts a sales meeting into a working session and dramatically raises the odds that both executives actually attend.
The proof of value is the third artifact and the one most often botched. Scope it before you scope anything else about the deal. A defensible proof runs against the bank's own historical data, sanitized and transferred under a mutual non-disclosure agreement and, at Tier-1, usually a separate data handling agreement that legal will need weeks to process. Start that legal thread the day the proof is agreed, not the day the data is ready. Define success criteria in writing before the data arrives — the specific metrics, the comparison baseline, and who signs off that the criteria were met. An undefined proof of value has no exit; it simply becomes a permanent free trial that the incumbent uses as evidence you are not production-ready.
Third-party risk and security review run in parallel with the proof, not after it. Ask in the first meeting who owns vendor risk, request the questionnaire immediately, and staff someone on your side to own responses. At a Tier-1, expect security architecture review, data residency questions, subcontractor disclosure, business continuity and disaster recovery evidence, and financial stability review. These are not obstacles to route around; they are the deal, and the sellers who treat them as first-class workstreams close on their forecast dates.

Model risk validation deserves its own thread wherever machine learning is involved. Banks validate models independently of the business that uses them, and validators want documentation: what the model does, what data trained it, how it was tested, how performance is monitored, and how a decision can be explained after the fact. Have that package ready as a standing asset rather than assembling it under deadline. In competitive situations, the completeness of the model documentation package is a genuine differentiator that most sellers never think to lead with.
Close the sequence by connecting it to renewal. The implementation plan attached to the order form should name the adoption metrics you will report at the first quarterly business review — analyst hours redeployed, alert volume at first-level review, scenarios tuned, cases closed in the platform. A renewal defended with usage evidence gathered from day one is a different conversation than a renewal defended with a relationship. Teach the room that the last five minutes of the sale are the first five minutes of the next one.

Running the 60 minutes as an actual training session
The session structure matters as much as the content, because a training the managers cannot repeat is a one-time event rather than an operating rhythm. Budget the hour deliberately: eight minutes on the two-wedge distinction, seven on Tier-1 versus Tier-2 motion differences, twelve running the decision tree live against real pipeline accounts, twelve on the numeric discovery set with paired role-play, thirteen on the sequencing artifacts, and eight on commitments and close.
Role-play is the only part that produces behavior change, so protect it. Pair the room, assign one seller and one executive persona, and give the executive persona a written card with three things: their title, one number they care about, and one objection they must raise. Rotate once so everyone plays both sides. Managers should inspect exactly one skill per call after the session rather than grading everything — the single most common coaching failure is a feedback list long enough that the rep changes nothing.
End with written commitments per rep: one named account, which wedge, which motion, and the next artifact they will produce with a date. Collect them. Review them at the following pipeline meeting. Training that ends without a per-rep artifact and a follow-up inspection is entertainment.
Related questions
Should a rep ever sell fraud and AML as a single bundled deal?
Rarely on the first land. Bundling asks two budget owners to co-fund an abstraction before either has seen a specific problem solved. Land one wedge with a clear owner and a measurable outcome, then use proven adoption to justify platform consolidation at expansion or renewal.
How do you handle a bank that says its false-positive rate is acceptable?
Stop arguing the rate and ask about consequences: analyst hours consumed, case aging, escalation backlogs, and what the last examination said about timeliness. The rate is a number the customer owns and will defend; the operational cost of that rate is a shared problem you can quantify together.
What changes when the competitor is the bank's internal build team?
Scope narrows and the pitch becomes about what the bank should not own. Target a specific hard layer — entity resolution, real-time latency, sanctions list maintenance — and frame the offer as freeing internal engineers for differentiated work rather than replacing their platform.
When should a seller disqualify a Tier-1 opportunity?
When there is no named compelling event, no executive sponsor who will attend a joint meeting, and no funded budget line — three consecutive misses. Tier-1 evaluations consume enormous pre-sales capacity, so an unqualified one is expensive even when it eventually closes.
How early should third-party risk review start?
The same day the proof of value is agreed. Security questionnaires, data handling agreements, and vendor assessments run on their own calendar and routinely determine the close date more than the technical evaluation does. Starting them after a successful proof adds months for no reason.
FAQ
Who actually signs a fraud or AML software deal at a bank?
The economic buyer is usually the Chief Risk Officer for fraud detection and the Chief Compliance Officer for AML and sanctions, but the signature path also includes procurement, third-party risk, information security, legal, and at larger institutions a model risk management function. The head of financial crime operations is rarely a signer and is almost always the person who determines whether the platform gets used after go-live, so treat operational buy-in as a gate rather than a courtesy.
How long should a rep expect these cycles to run?
Long enough that forecasting them optimistically will cost the rep credibility. Enterprise financial-crime deals routinely span multiple quarters because the technical evaluation, the proof of value against real data, and the third-party risk process are largely sequential in their dependencies even when run in parallel. The most reliable predictor of close date is not the technical evaluation but the status of the vendor risk and legal workstreams, which is why the training pushes reps to start those first.
What is the strongest opening for a bank running under an enforcement action?
Regulator-defensibility and remediation timeline, not fraud loss reduction. A bank in remediation has committed to specific fixes on specific dates, and its engineering and compliance capacity is allocated against those commitments. Show how your platform helps meet a commitment already made, with documentation an examiner can read, and you are helping rather than competing with the program office.
How should sellers talk about detection performance without overclaiming?
Only in terms of results produced on the customer's own sanitized data, with the comparison baseline and success criteria agreed in writing beforehand. Generic accuracy claims invite a technical audience to test them adversarially, and financial-crime evaluation teams are unusually good at that. A modest, verified improvement on the bank's data beats an impressive number the bank cannot reproduce.
What is the most common reason these deals stall after a successful proof of value?
An undefined success criterion and a missing executive decision forum. If nobody agreed in advance what "success" meant and who would declare it, a technically strong proof simply produces a request for a second proof. The fix is procedural: written criteria, a named sign-off, and a pre-scheduled decision meeting on the calendar before the proof begins.
How does a seller build renewal leverage during the initial sale?
By writing adoption metrics into the implementation plan attached to the order form and reporting them from the first quarterly business review onward. Usage evidence — analysts redeployed, alerts triaged in-platform, scenarios tuned, cases closed — is what makes a renewal a factual conversation rather than a relationship bet, and it is far easier to instrument at go-live than to reconstruct at month thirty.
Sources
- https://www.occ.gov/topics/supervision-and-examination/bsa/index-bsa.html
- https://www.fincen.gov/resources/statutes-and-regulations/guidance
- https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm
- https://www.ffiec.gov/bsa_aml_infobase/pages_manual/olm_toc.htm
- https://home.treasury.gov/policy-issues/financial-sanctions/specially-designated-nationals-and-blocked-persons-list-sdn-human-readable-lists
- https://www.fdic.gov/resources/supervision-and-examinations/consumer-compliance-examination-manual/
- https://www.eba.europa.eu/regulation-and-policy/anti-money-laundering-and-countering-financing-terrorism
- https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
- https://www.acams.org/en/resources
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
Related on PULSE
- [Identity Verification (IDV) Software Selling to Fintechs and Banks — 60-Min Training](/knowledge/st383)
- [Penetration Testing Services Selling to Tier-1 Enterprises — 60-Min Training](/knowledge/st384)
- [SIEM Software Selling to the Enterprise CISO — 60-Min Training](/knowledge/st386)
- [Manufacturing ERP Software Selling — 60-Min Training](/knowledge/st349)
- [Top 10 sales enablement drills for enterprise software reps](/knowledge/st0638)
- [Top 10 sales training workshops for enterprise software teams](/knowledge/st0637)
This page will be disappearing soon. Save it to your device for $1 — or read it free while it is here.
@Kory-White- · if Venmo asks, the last 4 of my number are 2012
This page is gone.
This one is off the shelf now. $1 keeps it on your phone for good — the whole page, pictures and diagrams included.









